APPLIED: [SRU][J][PATCH 0/1] CVE-2023-53320

Stefan Bader stefan.bader at canonical.com
Tue Sep 22 13:32:43 UTC 2026


On 18/09/2026 23:46, Cengiz Can via kernel-team wrote:
> https://ubuntu.com/security/CVE-2023-53320
> 
> [ Impact ]
> 
> In the Linux kernel, the following vulnerability has been resolved:
> 
> scsi: mpi3mr: Fix issues in mpi3mr_get_all_tgt_info()
> 
> The function mpi3mr_get_all_tgt_info() has four issues:
> 
> 1) It calculates valid entry length in alltgt_info assuming the header part of
> the struct mpi3mr_device_map_info would equal to sizeof(u32). The correct size
> is sizeof(u64).
> 
> 2) When it calculates the valid entry length kern_entrylen, it excludes one
> entry by subtracting 1 from num_devices.
> 
> 3) It copies num_device by calling memcpy(). Substitution is enough.
> 
> 4) It does not specify the calculated length to sg_copy_from_buffer(). Instead,
> it specifies the payload length which is larger than the alltgt_info size. It
> causes "BUG: KASAN: slab-out-of-bounds".
> 
> Fix the issues by using the correct header size, removing the subtraction from
> num_devices, replacing the memcpy() with substitution and specifying the
> correct length to sg_copy_from_buffer().
> 
> [ Fix ]
> 
> jammy/linux: clean cherry-pick of fb428a2005fc
> 
> [ Test Plan ]
> 
> Build and boot tested.
> 
> [ Where Problems Could Occur ]
> 
> The change is confined to the mpi3mr driver's handling of the get-all-target
> info driver command, so any regression would surface on systems using Broadcom
> MPI3-based SAS/NVMe storage controllers when userspace queries target
> information. Miscalculating the copy length could return truncated or malformed
> target data to management tools. Systems without mpi3mr hardware are not
> affected.
> 
> [ Other Info ]
> 
> Kybele flow-v12-15-gbd497840. Reference: c4b57794/v1
> 

Applied to jammy:linux/master-next. Thanks.

-Stefan
-------------- next part --------------
A non-text attachment was scrubbed...
Name: OpenPGP_signature.asc
Type: application/pgp-signature
Size: 833 bytes
Desc: OpenPGP digital signature
URL: <https://lists.ubuntu.com/archives/kernel-team/attachments/20260922/e0ef535a/attachment.sig>


More information about the kernel-team mailing list